5
CVSSv2

CVE-2020-27603

Published: 21/10/2020 Updated: 29/10/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

BigBlueButton prior to 2.2.27 has an unsafe JODConverter setting in which LibreOffice document conversions can access external files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bigbluebutton bigbluebutton

Github Repositories

Proof of Concept of Libreoffice file exfiltration vulnerability in Big Blue Button

CVE-2020-27603-bbb-libreoffice-poc Proof of Concept of Libreoffice file exfiltration vulnerability in Big Blue Button These ODT files show how to exploit a file exfiltration vulnerability that can happen with server-side Libreoffice rendering, eg BigBlueButton Background: bloghboeckde/archives/902-File-Exfiltration-via-Libreoffice-in-BigBlueButton-and-JODConverter